The transaction gap in digital banking is the period between an identity check and a later in-app action with meaningful consequences. A customer may authenticate successfully when opening an application, but actions such as adding a beneficiary, increasing a payment limit or authorising another device happen after that initial check.
The transaction gap in digital banking matters because access and action are not the same event. Login establishes that the expected credentials, device or biometric were presented at a particular moment. It does not automatically confirm who remains in control when money is moved or account information is changed later.
Where the transaction gap begins
A digital banking session usually begins with one or more authentication controls. These may include a password, one-time PIN, recognised device or biometric check.
Once access is granted, the customer can move through different parts of the application. Some actions, such as viewing a balance, have limited immediate consequences. Others can change who controls the account, where money is sent or how future activity is approved.
The transaction gap becomes relevant when the identity confidence established earlier is relied on during one of these later actions.
Why a valid session may still be misused
A valid session does not necessarily mean the banking platform has been technically compromised.
Credentials may have been obtained through phishing or a fraudulent support call. A one-time PIN may be intercepted following a SIM swap. A criminal may also gain remote control of a customer’s recognised device.
The South African Banking Risk Information Centre warns that Remote Access Trojan software can allow criminals to view a screen, capture credentials and execute transactions from a victim’s device. To the application, several expected signals may still appear correct.
This distinction helps explain why authentication can work as intended even when the person directing the session has changed.
Which actions carry greater consequences?
The level of risk can change throughout a session. Actions that may warrant greater identity confidence include:
- Adding a new beneficiary
- Approving a high-value payment
- Increasing a transaction limit
- Changing a payout account
- Linking an external wallet
- Authorising another device
- Replacing contact information
- Redirecting transaction alerts
These actions do more than provide information. They can change account control, move funds or make later fraud more difficult to detect.
What do existing controls establish?
Different controls answer different questions.
A password or PIN shows that the correct secret was entered. A one-time PIN shows access to the channel that received it. Device recognition shows that the application is operating on an expected device. A biometric can confirm the authorised person’s presence at the moment the check takes place.
Transaction monitoring serves another purpose. It can assess whether an action differs from an established pattern or carries greater financial risk.
Each control remains valuable. The transaction gap does not mean these controls have failed. It identifies a point where the organisation may need renewed confidence in the person using the application.
How continuous identity assurance fits
Continuous identity assurance extends the identity question beyond the initial login. Its role is to help an organisation maintain confidence that the authorised person remains present as the session continues.
This can be particularly relevant around actions that are financially significant, change account control or are difficult to reverse.
Continuous Facial Recognition with Liveness is designed to provide this additional identity-assurance layer while complementing existing authentication, device and transaction controls.
What continuous identity assurance does not establish
Identity assurance focuses on who is interacting with the application. It does not determine whether a payment is sensible, whether malware is present or whether a legitimate customer has been manipulated into completing a transaction.
Those risks require other measures, including device security, transaction monitoring, payment controls, customer education and fraud investigation.
The distinction prevents one security measure from being treated as a complete fraud-prevention strategy.
How Datanamix supports identity assurance beyond login
Datanamix provides Continuous Facial Recognition with Liveness as part of its identity and verification technology portfolio.
The solution helps banks, fintechs and other financial-services organisations extend identity assurance into active digital sessions while building on the authentication and fraud controls they already use.
Book a demo with Datanamix to discuss where additional identity assurance could support higher-risk in-app actions.









